Patch Tuesday, August EditionVulnerability in Vector Markup Language Could Allow Remote Code Execution (938127)
這篇真的不宜從置頂退下來, 都已經過了這麼久, M$ 仍然沒有完全解除
VML Vulnerability 的紅色警報, 若非小弟是個好奇寶寶, 否則就會讓這則更新默默偷溜過去...
以下雖然是舊聞, 不過還是值得參考
Wednesday, September 20, 2006
VML Exploit - Internet ExplorerUse this link with IE to see an example of VML. If you have the dll registered, you'll see a clock. Once unregistered, you shouldn't see anything.
Microsoft's Outlook e-mail client is also potentially vulnerable for this exploit. But fortunately e-mail is treated as if from Restricted Sites by default, where Binary and Scripting Behaviors is disabled. By using a web-mail client and Internet Explorer you might still be vulnerable.
不過好家在的是, 經過以上實驗(IE only), 只要您曾經解除 regsvr32 /u "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll", 則M$ 只更新, 並未將 vgx.dll 註冊回來, 所以您
暫時不用擔心(不過小弟還是把以上指令又執行一遍), 但將來是永遠說不準的...